Privacy Policy

Last updated: March 2026

1. Who we are

GemJam is an inventory management platform built for UK dealers of unique items, including jewellery, watches, antiques, and luxury goods. GemJam is operated by GemJam Ltd, a company registered in England and Wales.

For the purposes of UK data protection law, GemJam Ltd is the data controller for the personal data we collect about you (such as your account details, contact information, and how you use our website). When you store business data in GemJam (such as your inventory, transactions, and contacts), we act as a data processor on your behalf.

If you have any questions about this policy or how we handle your data, you can contact us at:

2. What data we collect

We collect different types of personal data depending on how you interact with GemJam:

Account data

When you create an account, we collect your name, email address, and password (managed securely by our authentication provider). If you add a profile picture, we store that too.

Organisation data

When you set up your organisation in GemJam, we collect your business name and any organisation settings you configure.

Business data you store in GemJam

This includes your inventory records, purchase and sale transactions, contact details for your suppliers and customers, item images, and any other data you enter into the platform. You are the controller of this data — we process it on your behalf to provide the service.

Payment and billing data

We use Stripe as our payment processor. Stripe collects your payment details (such as card number and billing address) directly. We do not see or store your full payment card details. We receive limited billing information from Stripe, such as your name, email, and transaction history, to manage your subscription.

Usage data

When you use GemJam, we automatically collect technical information including your IP address (which is discarded by our analytics provider and not stored — see section 10), browser type, device information, pages you visit, and how you interact with the platform. This helps us improve the service and diagnose issues.

Cookies

We use cookies and similar technologies. See section 10 for full details.

3. Why we collect your data and our lawful basis

Under UK GDPR, we must have a lawful basis for processing your personal data. Here is what we use your data for and why we are allowed to:

PurposeLawful basis
Providing the GemJam service (hosting your inventory, processing transactions, managing your account)Contract — necessary to deliver the service you signed up for
Processing payments and managing your subscriptionContract — necessary to fulfil our agreement with you
Sending you important service communications (e.g. changes to your account, security alerts, billing notifications)Contract — necessary to keep you informed about the service
Improving the platform, fixing bugs, and analysing how features are usedLegitimate interests — to improve and develop our service
Protecting against fraud, abuse, and security threatsLegitimate interests — to keep our platform and users safe
Sending you marketing communications about GemJam (only with your permission)Consent — you can withdraw this at any time
Complying with tax, legal, and regulatory obligationsLegal obligation — required by UK law

4. How we use your data

We use your personal data to:

  • Create and manage your account, and authenticate you when you sign in
  • Host and deliver the GemJam platform, including storing your inventory, transactions, contacts, and images
  • Process your subscription payments through Stripe
  • Send you service-related communications (account changes, security alerts, billing updates)
  • Provide customer support when you contact us
  • Monitor and improve the platform’s performance, reliability, and features
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with our legal obligations (such as tax record-keeping)

We do not sell your personal data to anyone. We do not use your data for automated decision-making or profiling.

5. Who we share your data with

We share your data with a limited number of trusted third-party service providers who help us run GemJam. Each provider only receives the data they need for their specific purpose, and we have data processing agreements in place with each of them.

ServicePurposeData shared
ClerkAuthentication and user account managementName, email address, profile picture, session data, IP address
StripePayment processing, subscription management, and billingName, email, billing address, payment details (Stripe processes payments on our behalf and does not share your card details with us)
NeonDatabase hosting (PostgreSQL)All data stored in GemJam (inventory, transactions, contacts, account data)
VercelApplication hosting, serverless functions, and content deliveryIP address, browser information, request data (processed ephemerally for serving the application)
ImageKitImage storage and delivery (CDN) for item photographsItem images you upload, delivery logs (IP addresses)
PostHogProduct analytics, error monitoring, and session replayPseudonymised usage data (page views, feature interactions, client-side errors), session recordings with all form inputs automatically masked and additional sensitive content (financial data, personal details) masked where developers have applied data attributes. No direct identifiers (e.g. email, name) are sent to PostHog; pseudonymous identifiers and usage data may still constitute personal data under UK GDPR. IP addresses are discarded at ingestion and are not stored. You can opt out via Settings > Preferences > Privacy

We may also share your data if we are required to by law, regulation, or legal process (for example, in response to a court order or request from HMRC).

If GemJam is acquired by or merged with another company, your data may be transferred as part of that transaction. We would notify you before your data is transferred and becomes subject to a different privacy policy.

6. International data transfers

Some of our service providers process data outside the United Kingdom. We ensure that appropriate safeguards are in place for all international transfers of personal data, as required by UK GDPR.

Here is where your data may be processed:

ServiceLocationSafeguard
Neon (database)AWS Europe West 2 (London, United Kingdom)UK data residency; DPA in place
Clerk (authentication)United States (Google Cloud)UK Extension to the EU-US Data Privacy Framework; DPA in place
Stripe (payments)United Kingdom, United StatesUK entity (Stripe Payments UK Ltd); DPA in place
Vercel (hosting)United States (primary); global edge network for content deliveryUK Extension to the EU-US Data Privacy Framework; DPA in place
ImageKit (images)AWS — configurable region (Europe available)EU-US Data Privacy Framework (UK Extension); DPA available
PostHog (analytics)European Union (Frankfurt, Germany)EU data residency; DPA in place

Where data is transferred to the United States, our providers are certified under the EU-US Data Privacy Framework with the UK Extension (also known as the UK-US Data Bridge), which has been recognised by the UK government as providing adequate protection for personal data.

7. How long we keep your data

We keep your data for as long as necessary for the purposes described in this policy. Here are the specific retention periods:

Data typeHow long we keep it
Account dataFor the duration of your account, plus 30 days after deletion to allow for recovery
Business data (inventory, transactions, contacts)For the duration of your account. Deleted within 90 days of account closure
Item imagesFor the duration of your account. Deleted from our image storage provider within 90 days of account closure
Billing and payment records7 years after the end of your subscription (as required by UK tax law)
Usage and technical logsUp to 12 months, then automatically deleted
Support communicationsFor the duration of your account, plus 2 years after account closure

When you cancel your account, we use a soft-delete approach. Your data is marked as deleted and becomes inaccessible, but is retained briefly in case you change your mind. After the retention period, your data is permanently and irreversibly deleted from our systems and those of our processors.

8. Your rights

Under UK data protection law, you have the following rights over your personal data:

  • Right of access — You can ask us for a copy of the personal data we hold about you.
  • Right to rectification — You can ask us to correct any personal data that is inaccurate or incomplete.
  • Right to erasure — You can ask us to delete your personal data. We may need to keep some data where we have a legal obligation (for example, billing records for tax purposes).
  • Right to restrict processing — You can ask us to temporarily stop processing your data while a concern is resolved.
  • Right to data portability — You can ask us to provide your data in a structured, commonly used, machine-readable format so you can transfer it to another service.
  • Right to object — You can object to our processing of your data where we rely on legitimate interests. You have an absolute right to object to direct marketing at any time. To opt out of product analytics, go to Settings > Preferences > Privacy within GemJam.
  • Right to withdraw consent — Where we process your data based on your consent (such as marketing emails), you can withdraw that consent at any time.

How to exercise your rights

To make a request, email us at privacy@gemjam.app. We will respond within one month. If your request is complex, we may extend this by up to two further months, but we will let you know within the first month.

There is no fee for making a request. We may ask you to verify your identity before processing your request.

Complaints

If you are unhappy with how we have handled your data, we encourage you to contact us first at privacy@gemjam.app so we can try to resolve the issue.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s data protection regulator:

9. Data security

We take the security of your data seriously and use appropriate technical and organisational measures to protect it. These include:

  • Encryption — All data is encrypted in transit using TLS (HTTPS). Data at rest is encrypted by our hosting and database providers.
  • Multi-tenant isolation — Every organisation’s data is completely isolated using row-level security (RLS) in the database. It is technically impossible for one organisation to access another’s data.
  • Authentication — We use Clerk, an enterprise-grade authentication provider, for secure sign-in and session management.
  • Access controls — Access to production systems is strictly limited and requires authentication.
  • Regular backups — Our database provider maintains automated backups to protect against data loss.

No system is completely secure. If we become aware of a data breach that affects your personal data, we will notify you and the ICO as required by law.

10. Cookies and tracking

Cookies are small text files stored on your device when you visit a website. We use cookies for the following purposes:

Essential cookies

These are necessary for GemJam to work. They include cookies for authentication (keeping you signed in) and security. You cannot opt out of these cookies as the service would not function without them.

CookieProviderPurpose
Session cookiesClerkKeep you signed in and manage your authentication session
Security cookiesClerk / VercelProtect against cross-site request forgery and other security threats

Analytics cookies

We use PostHog, a product analytics platform hosted in the European Union, to understand how our features are used and to diagnose errors. PostHog sets cookies to distinguish between users across sessions and to support session replay. These cookies are first-party (set on our domain) and do not track you across other websites.

CookieProviderPurposeExpiry
ph_phc_*_posthogPostHogStores a pseudonymous device identifier and session ID for analytics. Most analytics data (session replay configuration, feature flags) is kept in your browser’s localStorage, not in this cookie1 year
__ph_opt_in_out_<token>PostHogRecords your analytics opt-out preference (set when you disable analytics in Settings)1 year

PostHog analytics data is processed on our behalf under a data processing agreement. Session recordings automatically mask all form inputs. Other sensitive content (financial data, personal details) is masked or blocked where our developers have applied privacy attributes (data-ph-mask, data-ph-block). No direct identifiers (such as your email or name) are included in the analytics data we send to PostHog; pseudonymous identifiers and usage data may still constitute personal data under UK GDPR. IP addresses are discarded at ingestion and are not stored.

Consent and lawful basis: In accordance with the Privacy and Electronic Communications Regulations (PECR), we do not set analytics cookies on your device until you have signed in and have not opted out of analytics. When you first visit GemJam, our analytics service runs in memory only — no cookies or other data are stored on your device. Analytics cookies are only placed after you sign in, at which point your analytics preference is known. The underlying data processing is carried out under our legitimate interest in understanding how GemJam is used and diagnosing errors (see section 3). Before you sign in, pseudonymous analytics events (such as page views and errors) may still be sent to our analytics provider for error monitoring, but no data is stored on your device and IP addresses are discarded at ingestion.

Opting out: You can disable analytics at any time by going to Settings > Preferences > Privacy within GemJam. When you opt out, client-side analytics collection stops immediately, analytics cookies are removed from your device, and no new cookies will be set. A small number of server-side operational events with pseudonymised identifiers (and no direct identifiers such as name or email) may still be recorded. You can also block analytics cookies through your browser settings.

Managing cookies

You can control cookies through your browser settings. Please note that disabling essential cookies may prevent you from using GemJam.

11. Children’s data

GemJam is a business-to-business service designed for trade professionals. It is not intended for use by anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@gemjam.app and we will delete it.

12. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the “last updated” date at the top of this page.

For significant changes that affect how we process your personal data, we will notify you by email or through a notice in the GemJam application before the changes take effect.

Contact us

If you have any questions about this privacy policy or how we handle your data, please get in touch: